ATT&CKReferencesESET Security Mispadu Facebook Ads 2019

ESET Security Mispadu Facebook Ads 2019

ESET Security. (2019, November 19). Mispadu: Advertisement for a discounted Unhappy Meal. Retrieved March 13, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareMispadu

Mispadu uses a custom algorithm to obfuscate its internal strings and uses hardcoded keys.

Mispadu also uses encoded configuration files and has encoded payloads using Base64.

T1041
Exfiltration Over C2 Channel
MalwareMispadu

Mispadu can sends the collected financial data to the C2 server.

T1056.001
Keylogging
MalwareMispadu

Mispadu can log keystrokes on the victim's machine.

T1057
Process Discovery
MalwareMispadu

Mispadu can enumerate the running processes on a compromised host.

T1059.005
Visual Basic
MalwareMispadu

Mispadu’s dropper uses VBS files to install payloads and perform execution.

T1082
System Information Discovery
MalwareMispadu

Mispadu collects the OS version, computer name, and language ID.

T1083
File and Directory Discovery
MalwareMispadu

Mispadu searches for various filesystem paths to determine what banking applications are installed on the victim’s machine.

T1113
Screen Capture
MalwareMispadu

Mispadu has the ability to capture screenshots on compromised hosts.

T1115
Clipboard Data
MalwareMispadu

Mispadu has the ability to capture and replace Bitcoin wallet data in the clipboard on a compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwareMispadu

Mispadu decrypts its encrypted configuration files prior to execution.

T1176.001
Browser Extensions
MalwareMispadu

Mispadu utilizes malicious Google Chrome browser extensions to steal financial data.

T1204.002
Malicious File
MalwareMispadu

Mispadu has relied on users to execute malicious files in order to gain execution on victim machines.

T1218.007
Msiexec
MalwareMispadu

Mispadu has been installed via MSI installer.

T1218.011
Rundll32
MalwareMispadu

Mispadu uses RunDLL32 for execution via its injector DLL.

T1497.001
System Checks
MalwareMispadu

Mispadu can run checks to verify if it is running within a virtualized environments including Hyper-V, VirtualBox or VMWare and will terminate execution if the computer name is “JOHN-PC.”

T1518.001
Security Software Discovery
MalwareMispadu

Mispadu can list installed security products in the victim’s environment.

T1547.001
Registry Run Keys / Startup Folder
MalwareMispadu

Mispadu creates a link in the startup folder for persistence. Mispadu adds persistence via the registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1555
Credentials from Password Stores
MalwareMispadu

Mispadu has obtained credentials from mail clients via NirSoft MailPassView.

T1555.003
Credentials from Web Browsers
MalwareMispadu

Mispadu can steal credentials from Google Chrome.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.